Encrypted at rest
OAuth refresh tokens and any mailbox credentials are encrypted with AES-256-GCM before they touch our database. Encryption keys are stored separately from the data they protect.
Your mailbox is the most sensitive asset we touch. Here is how Warmerly protects it, what data we store, and who we work with to run the service.
Connecting a mailbox is not the same as trusting it. Each account you link is authenticated against its provider, its domain records are verified, and only then does it enter the sending path.
The same gate applies to every peer mailbox in the warmup network, so your mail is never exchanged with an account we cannot vouch for.

OAuth refresh tokens and any mailbox credentials are encrypted with AES-256-GCM before they touch our database. Encryption keys are stored separately from the data they protect.
Every request to Warmerly is served over TLS 1.2 or higher. Internal service-to-service calls and outbound mailbox connections enforce TLS as well.
We connect Gmail and Microsoft 365 mailboxes through Google and Microsoft OAuth. We do not ask for, store, or transmit SMTP passwords or app passwords for these providers.
We request only the OAuth scopes required to send, read, and organise warmup messages. You can revoke access from your Google or Microsoft account at any time.
Warmerly is hosted in the European Union. Primary databases run on Hetzner infrastructure in Falkenstein and Helsinki, with backups kept in the same region.
Encrypted, point-in-time backups run continuously with a 30 day retention window. Backups inherit the same encryption and access controls as production.
OAuth tokens are deleted immediately on mailbox disconnect. Account data is removed within 90 days of an account deletion request, except where retention is required by law.
Authentication is the part of deliverability that is genuinely binary: either the records are right or receiving servers cannot confirm you are who you claim to be. Warmerly re-checks all four record types daily on every connected domain, plus a blacklist lookup.
When something breaks — an expired selector, a DNS edit, a registrar migration — you hear about it before your next campaign does.

Warmerly acts as a data processor on behalf of customers and as a data controller for account information. We honour data subject rights including access, correction, deletion, and portability.
A signed Data Processing Addendum is available for every paid plan. Read or download our standard Data Processing Addendum.
A full, current sub-processor list — with data categories, location, and the date each was added — is on our Sub-processors page, or in the DPA.
Straight answers for Google Workspace and Microsoft 365 admins evaluating Warmerly, drawn directly from how the integration is built.
We monitor warmup dispatch, OAuth refresh, and the dashboard around the clock. Incidents and scheduled maintenance are posted to our public status page.
View status pageWarmerly is a trading name operated by Kristiyan Tsvetanov, a self-employed sole trader based in the United Kingdom.
Trust signals should come from outside, not just us. If you use Warmerly, leaving an honest review on any of these platforms helps others make a better-informed decision.
Security work protects your credentials. Sender health protects your ability to reach anyone at all. Warmerly watches both, and surfaces the four numbers that decide whether a domain is treated as trustworthy.
Blocklist status is checked against the public lists that mailbox providers actually consult, so a listing shows up as an alert rather than as a mysterious collapse in reply rate.

Send us your questionnaire, request a DPA, or ask about regional hosting. We respond within one business day.